Pricing

One paid plan. Fifty hosts, the daily CVE feed, and every feature Noxen has, for $12 a month. Three hosts are free forever - no card, no trial clock.

Free

$0

  • 3 hosts
  • Manual scans
  • Snapshot CVE feed (per release)
  • Never expires
Download free

No card. macOS 26+, signed and notarised.

Noxen

$12 /month

  • 50 hosts
  • Daily CVE feed - same-day coverage of new disclosures
  • Scheduled nightly scans
  • Webhooks, SIEM export, compliance mapping, custom checks
  • 30-day full-feature trial

Everything Noxen does. Most homelabs run 5–15 hosts; 50 leaves room for the ones you have not built yet.

Running more than 50 hosts, or managing client fleets? A multi-tenant MSP plan is in design and not yet on sale - we would rather say that than take money for a page of features. What is planned, and what exists today →

Side-by-side

Compare tiers

What you get in each tier, in one row-per-feature view.

  Free Noxen
Price $0 $12/month, or $120/year
Host cap 3 50
Scheduled scans Manual only Nightly
CVE feed cadence Per-release snapshot Daily
Slack / Discord / Teams webhooks - Yes
SIEM export (Wazuh / Splunk / ELK / Loki) - Yes
Compliance mapping (CIS v8, SOC 2, ISO 27001) - Yes
Custom checks - Yes
Trial n/a - the free tier does not expire 30 days, full features, no card
Support Community Email, business-day reply

Two columns, because there are two things you can buy. Everything Noxen can do is in the paid one - there is no feature held back for a higher tier that does not exist yet.

Frequently asked questions

Is Noxen a subscription?

Yes - $12/month, or $120/year, which works out at two months free. The CVE feed is rebuilt, re-indexed and re-signed every day, and that is a daily cost, so the price that pays for it recurs too. Cancel whenever you like: the app drops back to the free tier rather than stopping.

What do I get that the free tier does not have?

Fifty hosts instead of three, the daily CVE feed instead of the per-release snapshot, scheduled nightly scans, Slack / Discord / Teams webhooks, NDJSON SIEM export, CIS v8 / SOC 2 / ISO 27001 compliance mapping, and custom checks. There is one paid plan and it contains everything.

Is there a free trial?

Yes - 30 days, every feature, no card. Thirty rather than fourteen because Noxen proves itself the morning a new CVE lands on a host you own, and a fortnight may not contain one. The free tier (3 hosts, manual scans, snapshot feed) is not time-limited.

What happened to the one-time licence?

It was retired. The old price list had a $79 one-time tier sitting next to a $19/month tier that bought four times the hosts and a better feed - the flagship option was the worst value on the page. One plan at $12/month replaces all of it. Nobody had bought the one-time licence, so nobody was moved off anything.

Do I need to run anything on my remote hosts?

No. Noxen is agentless - it connects over SSH using a key you already have and reads package inventory, sshd_config, authorized_keys, and a few other inspection points. No agent to install, update, or worry about when a host is decommissioned.

Does Noxen send my data anywhere?

No. Scan results live in your local SwiftData store on your Mac. Nothing is uploaded to Noxen servers - the only outbound traffic from the app is the signed CVE feed download and (if enabled) webhook deliveries to endpoints you configure. There is no shared dashboard URL, no public link, no telemetry on what you scan or find.

Why Developer ID rather than the Mac App Store?

The App Sandbox blocks access to ~/.ssh/config and raw sockets, both of which Noxen needs. Developer ID notarisation gives us the same Gatekeeper trust model without the sandbox limits. More detail here.